Information Security Awareness in the Insurance Sector: Cognitive and Internal Factors and Combined Recommendations

被引:1
|
作者
Djotaroeno, Morgan [1 ]
Beulen, Erik [2 ]
机构
[1] Dux Grp, Consultant Proc & Informat Management, NL-3011 TA Rotterdam, Netherlands
[2] Univ Manchester, Management Sci & Mkt, Manchester M15 6PB, England
关键词
security awareness; information security awareness; cyber awareness; individual factors; employee awareness; situation awareness; security consciousness; insurance sector; POLICY COMPLIANCE; SITUATION AWARENESS; IMPACT; RESILIENCE; REQUIREMENTS; ANTECEDENTS; MANAGEMENT; BEHAVIOR;
D O I
10.3390/info15080505
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybercrime is currently rapidly developing, requiring an increased demand for information security knowledge. Attackers are becoming more sophisticated and complex in their assault tactics. Employees are a focal point since humans remain the 'weakest link' and are vital to prevention. This research investigates what cognitive and internal factors influence information security awareness (ISA) among employees, through quantitative empirical research using a survey conducted at a Dutch financial insurance firm. The research question of "How and to what extent do cognitive and internal factors contribute to information security awareness (ISA)?" has been answered, using the theory of situation awareness as the theoretical lens. The constructs of Security Complexity, Information Security Goals (InfoSec Goals), and SETA Programs (security education, training, and awareness) significantly contribute to ISA. The most important research recommendations are to seek novel explaining variables for ISA, further investigate the roots of Security Complexity and what influences InfoSec Goals, and venture into qualitative and experimental research methodologies to seek more depth. The practical recommendations are to minimize the complexity of (1) information security topics (e.g., by contextualizing it more for specific employee groups) and (2) integrate these simplifications in various SETA methods (e.g., gamification and online training).
引用
收藏
页数:29
相关论文
共 18 条
  • [1] Information security awareness in a developing country context: insights from the government sector in Saudi Arabia
    AlMindeel, Raneem
    Martins, Jorge Tiago
    INFORMATION TECHNOLOGY & PEOPLE, 2021, 34 (02) : 770 - 788
  • [2] Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs
    Tsohou, Aggeliki
    Karyda, Maria
    Kokolakis, Spyros
    COMPUTERS & SECURITY, 2015, 52 : 128 - 141
  • [3] Impact of comprehensive information security awareness and cognitive characteristics on security incident management-an empirical study
    Thangavelu, Manisekaran
    Krishnaswamy, Venkataraghavan
    Sharma, Mayank
    COMPUTERS & SECURITY, 2021, 109
  • [4] Compliance With Information Security Policies in the Slovene Insurance Sector
    Bernik, Igor
    PROCEEDINGS OF THE 15TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2016), 2016, : 28 - 33
  • [5] Factors Influencing Employees' Information Security Awareness in the Telework Environment
    Zhen, Jie
    Dong, Kunxiang
    Xie, Zongxiao
    Chen, Lin
    ELECTRONICS, 2022, 11 (21)
  • [6] Modelling the effects of personal factors on information security awareness
    Albayrak, Ebru
    Bagci, Hakki
    JOURNAL OF INFORMATION SCIENCE, 2025, 51 (01) : 20 - 30
  • [7] THE ANALYSIS OF FACTORS INFLUENCING AN INFORMATION SECURITY AWARENESS OF STUDENTS
    Beranek, Ladislav
    Remes, Radim
    EFFICIENCY AND RESPONSIBILITY IN EDUCATION 2015, 2015, : 34 - 41
  • [8] Awareness of digital information security in Hungarian public administration sector
    Illessy Miklos
    Nemeslaki Andras
    Som Zoltan
    INFORMACIOS TARSADALOM, 2014, 14 (01): : 52 - +
  • [9] Determinants of Information Security Awareness and Behaviour Strategies in Public Sector Organizations among Employees
    Al-Shanfari, I
    Yassin, Warusia
    Tabook, Nasser
    Ismail, Roesnita
    Ismail, Anuar
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (08) : 479 - 490
  • [10] Information Security Awareness in Educational Institution: An Analysis of Students' Individual Factors
    Farooq, Ali
    Isoaho, Johanna
    Virtanen, Seppo
    Isoaho, Jouni
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 352 - 359